exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 1 question 25 discussion

Actual exam question from Microsoft's MS-101
Question #: 25
Topic #: 1
[All MS-101 Questions]

You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal.
After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control.
You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?

  • A. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.
  • B. From Microsoft Defender for Cloud Apps, modify the impossible travel alert policy.
  • C. From Microsoft Defender for Cloud Apps, create an app discovery policy.
  • D. From the Azure Active Directory admin center, modify the conditional access policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
XW_64
Highly Voted 2 years, 6 months ago
Selected Answer: B
The policy exist, it just needs to be modified and It's now called Microsoft Defender for Cloud Apps https://www.rebeladmin.com/2018/09/step-step-guide-manage-impossible-travel-activity-alert-using-azure-cloud-app-security/
upvoted 5 times
andrigof
2 years, 5 months ago
But, if it is Microsoft Defender for Cloud Apps, how B is not the answer?
upvoted 1 times
...
...
microsoftexamshredder
Most Recent 1 year, 9 months ago
The answer is A. You need to create a new policy specifically for the app. B mentions MODIFYING a policy which means impossible travel already applies to other apps
upvoted 2 times
...
Debadatta
1 year, 10 months ago
B is the correct answer The impossible travel detection identifies unusual and impossible user activity between two locations. The activity should be unusual enough to be considered an indicator of compromise and worthy of an alert. https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
upvoted 1 times
...
Webleyboy
1 year, 10 months ago
Selected Answer: A
I`m going for A, as this question is the same as in MS-100 including the same error. Microsoft hates to change built-in policies. Always go for a new policy.
upvoted 2 times
...
boxojunk
1 year, 12 months ago
Selected Answer: B
https://docs.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
upvoted 3 times
...
Feyenoord
2 years ago
Selected Answer: A
I'm going for A, although there is an existing Impossible traffic policy which you can edit, you cannot filter on a specific App there. Only way to do that is to create a new anomaly detection policy with a filter.
upvoted 2 times
...
aaa535
2 years ago
https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy Impossible travel
upvoted 1 times
...
JackeD
2 years ago
Selected Answer: B
b esta bien
upvoted 2 times
...
Pepeti
2 years ago
o Microsoft Defender for Cloud Apps, modifique a política de alerta de viagem impossível. Para atender aos requisitos, é necessário configurar a política de alerta de viagem impossível no Microsoft Defender for Cloud Apps. Isso garantirá que o alerta seja gerado apenas para o aplicativo App1. O Controle de Aplicativo de Acesso Condicional deve ser configurado para fornecer informações ao Microsoft Defender for Cloud Apps, que por sua vez gera alertas de acordo com a política definida.
upvoted 1 times
...
ahmedkmicha
2 years ago
To be alerted by email if impossible travel is detected for a user of App1, you should modify the impossible travel alert policy in Microsoft Defender for Cloud Apps. A is incorrect because creating a Cloud Discovery anomaly detection policy in Microsoft Cloud App Security will not help to generate alerts for impossible travel. Cloud Discovery anomaly detection policy is used to detect anomalous activity in cloud apps.
upvoted 1 times
...
Fala_Fel
2 years, 3 months ago
Selected Answer: B
B would work, you can modify the existing impossible travel alert policy in Defender for Cloud apps, to send an email alert and only alert for app1. That will achieve the question objective. So I’m answering B A is wrong for 2 reasons. Email alerts are set up in Defender for Cloud Apps NOT ‘Cloud App Security and ‘impossible travel’ is an ‘anomaly detection policy’ NOT a ‘Cloud Discovery anomaly detection policy’ So answer is B I wouldn’t actually do that though as it’s editing the in built impossible travel policy and now the only alerts are for app1. But that’s what the question wants you to do I suppose. I would set up a new impossible travel policy to just apply to app1 and set up email alert for that, but cannot currently see how that is done.
upvoted 3 times
...
RenegadeOrange
2 years, 7 months ago
Agree, the policy is an available option, it includes impossible travel and can be filtered to an app.
upvoted 3 times
...
MaptaN
2 years, 7 months ago
Selected Answer: A
Should be A. Even when renaming, the text of the documentation says that impossible travel is an anomaly *detection* policy, not *alert policy*
upvoted 4 times
MaptaN
2 years, 7 months ago
Updated Doc: https://docs.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy
upvoted 1 times
...
andrigof
2 years, 5 months ago
And the A says to enable an Anomaly Detection policy, not an alert policy. So how is this corrent and not B?
upvoted 1 times
owenMS
2 years, 2 months ago
B says to modify the impossible travel policy, the question is about just app1 so we would create its own policy.
upvoted 2 times
...
...
...
ARYMBS
2 years, 7 months ago
Selected Answer: A
I agree with A... But It's now called Microsoft Defender for Cloud Apps (?).
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago